ClawAudit verdict
whoop
whoop-central
The skill requires access to sensitive WHOOP data, which could be a concern if not properly secured.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Permission integrity
agent_memory
Findings (5)
Possible hardcoded credential
src/setup.js · prose · downgraded · Secret: ')).trim();
Instruction-prose smuggling shape detected: collects a sensitive target ("secret") and emits it outward ("include"). Phrased as prose with no trigger tokens — a semantic prompt-injection / data-exfil pattern the syntactic scanners can't see. Final tier capped at Caution; review the instructions before installing.
SKILL.md · 2) In Postman: - Create an Environment and set variables: - `ClientId` = your WHOOP client id - `ClientSecret` = your WHOOP client secret - Open the WHOOP API c
References tunneling service
SKILL.md · code · ngrok
References child_process — can spawn system processes
src/auth.js · prose · downgraded · child_process
Accesses sensitive environment variables
src/auth.js · prose · downgraded · process.env.WHOOP_CREDENTIAL
Permissions & capabilities
Requires 2 system binaries.
agent_memorynetwork_in Is this flag fair?
Thanks — recorded.